package com.ckc.auth.controller;

import org.springframework.security.access.prepost.PreAuthorize;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;

@RestController
@RequestMapping("/normal")
public class NormalController {

    @PreAuthorize("hasRole('ROLE_NORMAL')")
    @RequestMapping("/demo")
    public String normal(){
        return "普通用户权限";
    }
}
